External Resources
Official regulatory sources organised for practical work
A working index of official privacy, AI governance, and cybersecurity sources for research, drafting, verification, and internal reference.
GDPR, ePrivacy and supervisory authorities
Official guidance, legislation, and reference material from EU institutions, the Irish DPC, the ICO, and European data protection bodies.
Ireland — Data Protection Commission
Official guidance and legislation from the Irish supervisory authority.
United Kingdom — ICO and PECR
Guidance from the Information Commissioner’s Office, including PECR for cookies and electronic marketing.
EU Primary Legislation
The official legal texts as published in the Official Journal of the European Union.
GDPR (Regulation 2016/679)
European Commission — Policy and Transfers
Official Commission materials on data protection policy and cross-border transfer mechanisms.
The Commission’s central page for EU data protection policy.
ECPlain-language explanation of core GDPR concepts.
ECHow GDPR fits alongside related EU instruments.
ECIndex page for transfer mechanisms, adequacy, and EU–US topics.
ECEuropean Data Protection Board
The EU-level body responsible for consistent GDPR interpretation across the EU and EEA.
Main site for the European Data Protection Board.
EDPBOfficial guidance clarifying GDPR interpretation.
EDPBSearch guidelines, opinions, statements, and other publications.
EDPBPractical guidance designed for smaller organisations.
EDPBEDPS and EU Business Portals
The regulator for EU institutions plus practical portals for businesses operating in the single market.
EDPS
EU AI Act legislation and implementation material
Primary legal text, Commission implementation materials, and official governance resources for the EU AI Act.
Primary Legislation
The official legal text of the AI Act as published in the Official Journal.
Commission Guidelines and Implementation
Official Commission guidelines, practical examples, and implementation materials.
Regulatory framework
Central page for the AI Act, including risk levels, timeline, and governance.
ECLegal explanations and practical examples for the Article 5 prohibitions.
ECScope of obligations for general-purpose AI model providers under Chapter V.
ECOverview of guidelines in preparation for later stages of AI Act application.
ECAI Office and Governance
The EU governance structure responsible for AI Act implementation, enforcement, and coordination.
Governance bodies
The centre of AI expertise within the Commission, responsible for GPAI model enforcement.
ECOverview of the AI Board, Scientific Panel, Advisory Forum, and national authorities.
ECThe Member State coordination body advising on consistent AI Act application.
ECCybersecurity law, frameworks and incident guidance
Official cybersecurity sources spanning NIS2, ENISA, national cyber authorities, and widely used government frameworks.
Ireland — NCSC
Official guidance, incident reporting, and frameworks from Ireland’s national cybersecurity authority.
Official published guidance and templates for organisations.
NCSC IERisk-based cybersecurity framework for maturity and NIS2-aligned measures.
NCSC IEIreland’s NIS2 updates, FAQs, and implementation materials.
NCSC IEIrish statutory instrument implementing NIS obligations.
ISBUnited Kingdom — NCSC
Guidance and frameworks from the UK’s national cybersecurity authority, including Cyber Essentials.
Government-backed framework for organisational cyber risk management.
NCSC UKMinimum cyber security standard for organisations of all sizes.
NCSC UKGovernment guidance on the Cyber Essentials certification scheme.
GOV.UKUK Network and Information Systems Regulations legal text.
legislation.gov.ukEU Cybersecurity Law and ENISA
EU-wide cybersecurity legislation and guidance from the EU Agency for Cybersecurity.
EU-wide cybersecurity obligations for essential and important entities.
EUR-LexDetailed technical measures and significant incident criteria.
EUR-LexENISA mandate and EU cybersecurity certification framework.
EUR-LexProduct security requirements for connected hardware and software.
EUR-LexUnited States — NIST and CISA
Widely used US government cybersecurity frameworks and threat resources.
Official landing page for the Cybersecurity Framework and supporting resources.
NISTThe CSF 2.0 publication.
NIST (PDF)Security and privacy controls catalogue for assurance programmes.
NISTUS government hub for ransomware prevention and response.
CISAPut these sources to work
Acompli builds regulatory intelligence into your compliance workflow. Work from a governed knowledge base with regulatory intelligence built into your compliance workflow.